"Blackhat SEO has become the most prevalent threat facing end-users on the web today, surpassing social networking threats," said Michael Sutton, VP of Security Research at Zscaler. "Our research has shown that virtually any popular search term will contain malicious sites within the top 100 results at all major search engines including Google, Yahoo! and Bing. In some cases, up to 50% of search results are malicious. When combined with social engineering attacks such as delivering fake antivirus applications or fake software updates, these attacks are incredibly effective."
Sutton continued: "What is particularly concerning is the fact that fewer than 25% of anti-virus products can generally detect and block files associated with these attacks since they are so frequently changed."
How it Works
Malicious pages used in Blackhat SEO attacks deliver customized content based on the origin of the request. This is done in order to maintain stealth and extend the life of the attack. For example, malicious pages may first identify the web browser type and deliver a custom payload targeted at that specific platform. The attacks also check to see if the request originated from the search engine that was initially poisoned by the SEO attack. By masking the source of the request when a user follows search engine results for Google, Yahoo! and Bing, the attack is broken and the malicious content is never delivered to the victim. With a typical anti-virus detection rate below 25% for such attacks, the protection provided by Zscaler's SES solution can be a valuable asset in keeping PCs from falling victim to Blackhat SEO attacks.
Pricing & Availability
Search Engine Security (SES) is available immediately, free to all consumers.
To obtain a copy, please open your Firefox browser and navigate to http://zscaler.com/researchtools.html. Simply hit the "Add to Firefox" button and it will be integrated into the browser. You may then begin searching safely and with confidence!
Through a multi-tenant, globally-deployed infrastructure with 40+ data centers, Zscaler enforces business policy for web and email, mitigates risk and provides twice the functionality at a fraction of the cost of current solutions. It enables organizations to provide the right access to the right users, from any place and on any device. For more information, visit us at www.zscaler.com.